STIGQter STIGQter: STIG Summary: Samsung Android 11 with Knox 3.x AE Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 20 Nov 2020:

Samsung Android must be configured to disable trust agents. NOTE: This requirement is not applicable (NA) for specific biometric authentication factors included in the product Common Criteria evaluation.

DISA Rule

SV-230983r607691_rule

Vulnerability Number

V-230983

Group Title

PP-MDF-301150

Rule Version

KNOX-11-003900

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure Samsung Android to disable Trust Agents.

On the management tool, in the device restrictions section, set "Trust Agents" to "Disable".

Check Contents

Review Samsung Android configuration settings to determine if Trust Agents are disabled.

This validation procedure is performed on both the management tool Administration Console and the Samsung Android device.

On the management tool, in the device restrictions section, verify that "Trust Agents" are set to "Disable".

On the Samsung Android device:
1. Open Settings >> Biometrics and security >> Other security settings >> Trust agents.
2. Verify that all listed Trust Agents are disabled and cannot be enabled.

If on the management tool "Trust Agents" are not set to "Disable", or on the Samsung Android device a "Trust Agent" can be enabled, this is a finding.

Vulnerability Number

V-230983

Documentable

False

Rule Version

KNOX-11-003900

Severity Override Guidance

Review Samsung Android configuration settings to determine if Trust Agents are disabled.

This validation procedure is performed on both the management tool Administration Console and the Samsung Android device.

On the management tool, in the device restrictions section, verify that "Trust Agents" are set to "Disable".

On the Samsung Android device:
1. Open Settings >> Biometrics and security >> Other security settings >> Trust agents.
2. Verify that all listed Trust Agents are disabled and cannot be enabled.

If on the management tool "Trust Agents" are not set to "Disable", or on the Samsung Android device a "Trust Agent" can be enabled, this is a finding.

Check Content Reference

M

Target Key

5247

Comments